Vulnerabilities > Joyent > Smartos > High

DATE CVE VULNERABILITY TITLE RISK
2020-10-26 CVE-2020-27678 Classic Buffer Overflow vulnerability in multiple products
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022.
network
low complexity
illumos joyent omniosce CWE-120
7.5
2018-02-21 CVE-2018-1166 Improper Input Validation vulnerability in Joyent Smartos 20170803
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z.
local
low complexity
joyent CWE-20
7.2
2016-12-14 CVE-2016-9035 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9034 Classic Buffer Overflow vulnerability in Joyent Smartos 20120614/20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9033 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9032 Classic Buffer Overflow vulnerability in Joyent Smartos 20161110T013148Z
An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-120
7.0
2016-12-14 CVE-2016-9031 Integer Overflow or Wraparound vulnerability in Joyent Smartos 20161110T013148Z
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
high complexity
joyent CWE-190
7.8
2016-12-14 CVE-2016-8733 Integer Overflow or Wraparound vulnerability in Joyent Smartos 20120614/20161110T013148Z
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.
local
low complexity
joyent CWE-190
8.8
2012-06-12 CVE-2012-0217 Buffer Errors vulnerability in Freebsd
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application.
7.2